Threat Advisory

Alist SimpleHttp Offline-Download Flaw Lets Attackers Write Arbitrary Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The overall risk/impact is MEDIUM and affects version ranges not explicitly stated in the article. (CVSS 6.5 — Medium): An authenticated arbitrary file write vulnerability exists via Content-Disposition path traversal in SimpleHttp offline-download tool.

An attacker can traverse out of the temp directory to write any file the alist process can write, requiring a non-admin user with PermAddOfflineDownload permission on any path. (GHSA-x4q4-7phh-42j9, fsmanage/fsbatch path traversal patched in v3.57.0).[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The overall risk/impact is MEDIUM and affects version ranges not explicitly stated in the article. (CVSS 6.5 — Medium): An authenticated arbitrary file write vulnerability exists via Content-Disposition path traversal in SimpleHttp offline-download tool.

An attacker can traverse out of the temp directory to write any file the alist process can write, requiring a non-admin user with PermAddOfflineDownload permission on any path. (GHSA-x4q4-7phh-42j9, fsmanage/fsbatch path traversal patched in v3.57.0).[emaillocker id="1283"]

The offline-download `SimpleHttp` downloader was not in scope of that fix; the vulnerable code is on `main` HEAD as of the time of this report (verified against the openlistteam/openlist tree's.

RECOMMENDATION:

We recommend you to update github.com/OpenListTeam/OpenList to version 4.2.3.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu